[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: Fwd: Re: Son of IKE: A proposal for moving forward
On Thu, 13 Jun 2002, Bill Sommerfeld wrote:
> > There is no reason why the two trusted "networks" can't be single hosts --
> > that's just a degenerate case...
>
> there are certain obvious scaling problems with this approach.
> direct use of transport mode is likely to be easier to manage, require
> fewer addresses, and be simpler with large numbers of hosts.
You're making unwarranted assumptions about what a VPN is. It's perfectly
possible to have a VPN in which the "wires" are private but the addresses
are not. (Indeed, even VPNs with non-degenerate ends do not necessarily
use private addresses.)
Henry Spencer
henry@spsystems.net